3 ms·
Use a trusted distro like Ubuntu LTS. Install security updates automatically. Be aware and focus specifically on which ports/services are available from the in
by cypherg 4y ago
Use a trusted distro like Ubuntu LTS. Install security updates automatically.
Be aware and focus specifically on which ports/services are available from the internet.
If you absolutely need SSH, ensure you use something like fail2ban and use complex credentials. If possible, use obscurity to change from the default port of 22.
If you're running an internet-facing service, like nginx, ensure that it's always up to date.
Using SELinux and AppArmour and GRSecurity are usually way overkill and cumbersome to manage.
- deleted 4y ago[deleted]
- GOATS- 4y agoFail2ban serves no purpose other than bloating your firewall's denylist. You can mitigate most blind bruteforce attacks by just changing the port number of your SSH server and by using a public/private key pair instead of passwords.
- doubled112 4y agoWhile this obscurity doesn’t add much security, sure does clean up the logs, doesn’t it?
- CameronNemo 4y agoAppArmor is often pretty easy to use IME.